Web of trust is inside the system

Reply to this note

Please Login to reply.

Discussion

The WoT can only prove other people's trust in a key, but not who currently controls it. In fact, the moment someone else gets a hand on your private key, the WoT still proves trust in that key being yours, until you somehow notify your peers, so they can revoke that trust. But how are you going to do this within the system, if there are no means for sub keys and key rotation in the first place?

Similarly, for a new key, how can your peers trust it in the first place? The only way is to announce your key outside of the system, via a medium/transport that your peers are willing to trust.

Yup - with trust decisions made outside of the system.